public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Till Hofmann <thofmann@fedoraproject.org>
To: git-commits@fedoraproject.org
Subject: [rpms/log4cxx] epel8: Backport fix for CVE-2025-54812 (HTMLLayout logger-name XSS)
Date: Fri, 03 Jul 2026 11:23:04 GMT [thread overview]
Message-ID: <178307778401.1.10358718087171436814.rpms-log4cxx-d46dcae082b4@fedoraproject.org> (raw)
A new commit has been pushed.
Repo : rpms/log4cxx
Branch : epel8
Commit : d46dcae082b4a5517ac2b467ffc50907d4d56440
Author : Till Hofmann <thofmann@fedoraproject.org>
Date : 2026-07-03T12:47:07+02:00
Stats : +83/-1 in 2 file(s)
URL : https://src.fedoraproject.org/rpms/log4cxx/c/d46dcae082b4a5517ac2b467ffc50907d4d56440?branch=epel8
Log:
Backport fix for CVE-2025-54812 (HTMLLayout logger-name XSS)
HTMLLayout wrote the logger name unescaped into an HTML title="..."
attribute. If untrusted data controls the logger name, this allows
breaking out of the attribute and injecting HTML/JS into the
generated log file, which executes when opened in a browser.
Backports the escaping fix from upstream commit d617f0c00 (part of
the 1.5.0 release) to this package's 0.10.0 base by adding
Transform::appendEscapingQuote() and using it for the logger name in
HTMLLayout::format(). Validated locally: patch applies cleanly,
builds without errors under mock (rocky+epel-8-x86_64), and a manual
runtime test confirms a logger name containing a double quote is now
rendered as " instead of breaking out of the attribute.
Not pushed; local validation only.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---
diff --git a/log4cxx-0.10.0-CVE-2025-54812-htmllayout-quote-escape.patch b/log4cxx-0.10.0-CVE-2025-54812-htmllayout-quote-escape.patch
new file mode 100644
index 0000000..2265d0a
--- /dev/null
+++ b/log4cxx-0.10.0-CVE-2025-54812-htmllayout-quote-escape.patch
@@ -0,0 +1,73 @@
+--- a/src/main/cpp/htmllayout.cpp 2026-07-03 12:36:38.381749632 +0200
++++ b/src/main/cpp/htmllayout.cpp 2026-07-03 12:36:49.073857184 +0200
+@@ -105,7 +105,7 @@
+ output.append(LOG4CXX_EOL);
+
+ output.append(LOG4CXX_STR("<td title=\""));
+- output.append(event->getLoggerName());
++ Transform::appendEscapingQuote(output, event->getLoggerName());
+ output.append(LOG4CXX_STR(" logger\">"));
+ Transform::appendEscapingTags(output, event->getLoggerName());
+ output.append(LOG4CXX_STR("</td>"));
+--- a/src/main/cpp/transform.cpp 2026-07-03 12:36:38.381664738 +0200
++++ b/src/main/cpp/transform.cpp 2026-07-03 12:37:27.906949492 +0200
+@@ -115,3 +115,40 @@
+ buf.append(input, start, input.length() - start);
+ }
+
++void Transform::appendEscapingQuote(
++ LogString& buf, const LogString& input)
++{
++ static const LogString QUOTE(LOG4CXX_STR("\""));
++ static const LogString QUOTE_ENTITY(LOG4CXX_STR("""));
++
++ if(input.length() == 0 )
++ {
++ return;
++ }
++
++ LogString::size_type end = input.find(QUOTE);
++ if (end == LogString::npos)
++ {
++ buf.append(input);
++ return;
++ }
++
++ LogString::size_type start = 0;
++ while (end != LogString::npos)
++ {
++ buf.append(input, start, end-start);
++ buf.append(QUOTE_ENTITY);
++ start = end + 1;
++ if (start < input.length())
++ {
++ end = input.find(QUOTE, start);
++ }
++ else
++ {
++ return;
++ }
++ }
++
++ buf.append(input, start, input.length() - start);
++}
++
+--- a/src/main/include/log4cxx/helpers/transform.h 2026-07-03 12:36:38.384055125 +0200
++++ b/src/main/include/log4cxx/helpers/transform.h 2026-07-03 12:37:39.900978004 +0200
+@@ -55,6 +55,16 @@
+ */
+ static void appendEscapingCDATA(
+ LogString& buf, const LogString& input);
++
++ /**
++ * Add \c input to \c buf with double quote characters replaced with
++ * &quot;.
++ *
++ * @param buf output stream holding the data to this point.
++ * @param input The text to be converted.
++ */
++ static void appendEscapingQuote(
++ LogString& buf, const LogString& input);
+ }; // class Transform
+ } // namespace helpers
+ } //namespace log4cxx
diff --git a/log4cxx.spec b/log4cxx.spec
index d9bbcbc..4470be8 100644
--- a/log4cxx.spec
+++ b/log4cxx.spec
@@ -1,6 +1,6 @@
Name: log4cxx
Version: 0.10.0
-Release: 31%{?dist}
+Release: 32%{?dist}
Summary: A port to C++ of the Log4j project
License: ASL 2.0
@@ -13,6 +13,10 @@ Patch0: log4cxx-cstring.patch
# https://anonscm.debian.org/cgit/collab-maint/log4cxx.git/plain/debian/patches/170-gcc6-fix.patch
Patch1: log4cxx-gcc6.patch
Patch2: log4cxx-gcc6-tests.patch
+# Fixes CVE-2025-54812: HTMLLayout did not escape double quotes in the
+# logger name written into the HTML title="..." attribute, backported
+# from upstream commit d617f0c00 (fixed upstream in 1.5.0)
+Patch3: log4cxx-0.10.0-CVE-2025-54812-htmllayout-quote-escape.patch
BuildRequires: apr-devel
BuildRequires: apr-util-devel
@@ -46,6 +50,7 @@ Documentation for %{name}.
%patch0 -p1
%patch1 -p1
%patch2 -p1
+%patch3 -p1
%build
sed -i.libdir_syssearch -e \
@@ -78,6 +83,10 @@ rm $RPM_BUILD_ROOT/%{_libdir}/liblog4cxx.la
%doc html/
%changelog
+* Fri Jul 03 2026 Till Hofmann <till.hofmann@posteo.de> - 0.10.0-32
+- Backport fix for CVE-2025-54812 (HTMLLayout logger name not escaped,
+ possible XSS in generated HTML log files)
+
* Tue Jul 28 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.10.0-31
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
reply other threads:[~2026-07-03 11:23 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178307778401.1.10358718087171436814.rpms-log4cxx-d46dcae082b4@fedoraproject.org \
--to=thofmann@fedoraproject.org \
--cc=git-commits@fedoraproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox